Privacy Policy

Effective Date: August 1, 2026


Health and Medical Disclaimer

This App is not a medical device and does not provide medical advice, diagnosis, or treatment. The App is intended for informational, educational, research, or wellness purposes only. Users should consult a qualified healthcare professional regarding any medical questions or conditions.


1. Purpose and Scope

This Privacy Policy describes how LSU's Pennington Biomedical Research Center ("PBRC," "we," "us," or "our") collects, uses, maintains, protects, and discloses information through the Diabetes Clinic mobile application (the "App").

The App is intended for adults only. Users must be 18 years of age or older. The App is not directed to children, and PBRC does not knowingly collect information from anyone under 18. The App is offered only to users in the United States and is not intended for use outside the United States.

This Policy covers two categories of information:

  • Protected Health Information (PHI) — information governed by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations. The PHI-specific provisions of this Policy apply only to information that constitutes PHI under HIPAA.
  • Non-PHI Information — device, technical, analytics, and other information that does not constitute PHI.

Where information qualifies as PHI, the PHI provisions of this Policy control. Non-PHI information is governed by the general provisions of this Policy.

2. PBRC's Role Under HIPAA

Depending on the App's function, PBRC may act as:

  • A HIPAA Covered Entity, or
  • A HIPAA Business Associate acting on behalf of health plans, health care providers, or other covered entities.

PBRC complies with applicable provisions of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule (45 C.F.R. Parts 160 and 164).

3. Definitions

  • Protected Health Information (PHI): Individually identifiable health information that relates to an individual's physical or mental health, health care, or payment for health care, and that identifies the individual or could reasonably be used to identify the individual.
  • Non-PHI Information: Information that does not identify an individual's health status or is not otherwise governed by HIPAA, such as certain device, technical, and analytics data.

4. Information We Collect

4.1 PHI We May Collect

Depending on App design and use, PHI may include:

  • Identifiers (e.g., name, date of birth, email address, participant ID);
  • Health-related information entered by users (e.g., survey responses, biometric measures, symptoms, wellness or lifestyle data);
  • Communications submitted through the App that contain health information;
  • App usage data linked to an identifiable individual.

PBRC collects only the minimum necessary PHI required to operate the App.

4.2 Non-PHI Information We May Collect

This Policy's non-PHI provisions apply to:

  • Device and technical data (e.g., IP address, device type, operating system);
  • App usage analytics not linked to identifiable health information;
  • Log data, crash reports, and performance metrics;
  • Communications that do not include PHI.

Protected Health Information, if collected through the App, is governed exclusively by the PHI provisions of this Policy. Where information qualifies as PHI, the PHI provisions control.

5. How We Use Information

5.1 Permitted Uses of PHI

PBRC may use PHI for purposes permitted by HIPAA, including:

  • Treatment: Supporting health-related services, education, or care coordination, as applicable;
  • Payment: Billing or reimbursement activities, where applicable;
  • Health Care Operations: App operation, quality improvement, analytics, compliance monitoring, auditing, training, and security;
  • Research: When permitted by law and applicable approvals (e.g., IRB approval, informed consent, or waiver);
  • As Authorized: Uses authorized by the individual, where required.

5.2 Uses of Non-PHI Information

PBRC uses non-PHI information to:

  • Operate and maintain the App;
  • Improve functionality and user experience;
  • Monitor performance, security, and reliability;
  • Conduct de-identified analytics and reporting.

6. How We Share and Disclose Information

6.1 Permitted Disclosures of PHI

PBRC may disclose PHI:

  • To vendors and service providers acting as Business Associates under written agreements;
  • To collaborating institutions or sponsors, when permitted by law and agreements;
  • As required by law or public health authorities;
  • To prevent a serious threat to health or safety;
  • To the individual or their authorized representative.

PBRC does not sell PHI and does not use PHI for marketing without valid authorization when required.

6.2 Sharing of Non-PHI Information

Non-PHI information may be shared with:

  • IT service providers and analytics vendors;
  • Cloud hosting and support providers;
  • Others as required by law.

7. Cookies and Tracking Technologies

The App may use limited tracking or analytics technologies for functionality and performance monitoring. These technologies do not replace or override HIPAA protections for PHI.

PBRC does not engage in cross-app tracking for advertising purposes.

8. Data Security and Safeguards

PBRC maintains administrative, technical, and physical safeguards designed to protect information, including:

  • Role-based access controls;
  • Encryption where appropriate;
  • Audit logs and monitoring;
  • Workforce training and confidentiality requirements;
  • Incident response and breach management procedures.

PBRC implements reasonable safeguards to protect non-PHI information from unauthorized access or disclosure.

9. Individual Rights

Individuals have rights under HIPAA, including the right to:

  • Access their PHI;
  • Request amendments;
  • Request an accounting of disclosures;
  • Request restrictions on certain uses or disclosures;
  • Request confidential communications;
  • Receive breach notifications when required.

10. Data Retention and Deletion

We retain personal information and other user data collected through the Diabetes Clinic app for as long as your account remains active or as needed to provide the app's services. You may delete your account and the data associated with it at any time. Within the App on both iOS and Android, an account-deletion option directs you to instructions for deleting your account and associated data. You may also delete your account by signing in at https://penningtondiabetesclinic.com/ and selecting Delete Account. When you delete your account, deletion takes effect immediately, and your account and associated app data are permanently deleted.

Where a use or disclosure of your information requires your authorization, you may revoke that authorization at any time.

We may retain limited information after an account is deleted only when required by applicable law or when reasonably necessary for security, fraud prevention, resolving disputes, enforcing our agreements, or maintaining legally required medical or business records. Information retained for one of these purposes will be limited to what is necessary, will not be used for other purposes, and will be kept only for the period required by applicable law or for as long as the stated purpose requires. It will then be securely deleted or de-identified.

Medical records maintained separately by Pennington Biomedical or another health care provider, including records maintained in an electronic health record system, may be subject to legal and regulatory retention requirements and are not deleted with your app account. Such records will be retained only for the period required by applicable law and will be securely disposed of when that period ends. Questions or requests concerning those records may be directed to the HIPAA Privacy Officer using the contact information provided in this policy.

11. Breach Notification

PBRC will provide breach notifications in accordance with HIPAA and applicable state law.

12. Platform-Specific Disclosures

12.1 Apple App Store Privacy Disclosures

Certain information collected through this App may be linked to an individual user, such as when associated with an account, patient identifier, or contact information. Other information may be collected or processed in a de-identified or aggregated form that is not linked to an individual.

PBRC's App Privacy Details disclosures in App Store Connect accurately reflect whether data is linked or not linked to users. PBRC does not track users across apps or websites owned by other companies for advertising or marketing purposes, as defined by Apple's App Tracking Transparency (ATT) framework.

12.2 Google Play Store — Data Safety Disclosures

This App is distributed through third-party platforms, including the Google Play Store, which require additional user-facing disclosures regarding data collection, use, sharing, and security practices.

This Policy is intended to align with the disclosures provided in the Google Play Console Data Safety section for this App. PBRC discloses, in both this Policy and the Google Play Data Safety section:

  • The categories of data the App collects;
  • The purposes for which data is used;
  • Whether data is shared and with whom;
  • The security practices applied to protect data;
  • User options regarding data access, retention, and deletion.

PBRC makes reasonable efforts to ensure that disclosures are accurate, complete, and consistent across this Privacy Policy, the App, and platform-specific disclosures.

12.3 Relationship Between This Policy and Platform Disclosures

Nothing in this Policy limits PBRC's obligations under HIPAA or applicable state law. Where this Policy and platform-specific disclosures address the same data practices, PBRC intends that they be interpreted consistently.

13. Changes to This Policy

PBRC may update this Privacy Policy from time to time. The Effective Date reflects the most recent revision. Continued use of the App constitutes acceptance of any changes.

14. Developer Identification

JPL Technical Solutions is the official developer of the Diabetes Clinic app. Their responsibilities encompass the design, implementation, and ongoing enhancement of the app, ensuring a seamless and functional user experience. They are dedicated to maintaining the highest standards of security, app performance, and reliability to effectively serve the needs of users.

15. Contact Information

PBRC Privacy Officer
Pennington Biomedical Research Center
6400 Perkins Road
Baton Rouge, LA 70808
Email: complianceofficer@pbrc.edu
Phone: 225-763-2500